Industry 4.0 connects machines – and widens the attack surface. This radar counts new security advisories (ICS-CERT) for the automation vendors that run German factories: Siemens, Phoenix Contact, WAGO, Beckhoff, SICK, Schneider, Rockwell, ABB and more.
Siemens Siveillance Control
Distribution of all tracked advisories by CVSS severity.
New advisories per month for the tracked vendors – rolling window; the red peak marks the busiest month.
Which automation vendors account for the most advisories. “DE” = headquartered in Germany.
More advisories doesn't mean “less secure” – large, widely deployed portfolios (e.g. Siemens) simply generate more reports.
The latest ICS-CERT advisories for the tracked vendors.
Siemens Siveillance Control
Siemens SIPLUS and SIMATIC Products
Siemens Desigo CC family
Siemens Industrial Edge Management
Siemens SIMOVE Fleetmanager and SIPLANT
Siemens WTV676 and WTV776
Mitsubishi Electric GX Works3 and Motion Control Settings
Hitachi Energy FACTS Control Platform (FCP)
Schneider Electric Modicon M340 Controller and Communication Modules
Schneider Electric NetBotz 5 750/755
ABB Ability Edgenius
Schneider Electric PowerChute Serial Shutdown
Schneider Electric SCADAPack x70 Products
Siemens Reyrolle 7SR5
Siemens Mendix SAML
Siemens Teamcenter
Rockwell Automation ControlFLASH
Rockwell Automation ArmorStart LT
Rockwell Automation 1756-ENBT Module
Rockwell Automation RSLinx Classic
Rockwell Automation Redundancy Module Configuration Tool
Rockwell Automation Logix Platform
Rockwell Automation FactoryTalk Activation Manager
Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
Rockwell Automation Historian ME
Rockwell Automation OTTO Fleet Manager
Siemens SIMATIC IoT2050 Advanced
Siemens Simcenter Nastran
Hitachi Energy APM Edge Product
Siemens License Server (SLS)
We read the ICS Advisory Project database – an open, structured mirror of every CISA ICS-CERT advisory – and keep the vendors that matter to DACH industry.
Source: the ICS Advisory Project (github.com/icsadvprj, CC-licensed), which structures the advisories of the US agency CISA. CISA tracks globally; the advisories concern products used worldwide, including in Germany. No AI model, no keys.
All figures without guarantee. Data source: ICS Advisory Project (mirror of CISA ICS-CERT advisories, CC). The vendor selection is curated (industrial automation relevant to DACH) and not exhaustive. An advisory doesn't mean your plant is affected – check the respective original advisory. i6eal is not a security authority.
How many new security advisories (ICS-CERT) exist for the automation vendors common in German factories – with severity, a vendor ranking, a monthly trend and the latest reports.
From the ICS Advisory Project, an open structured database of all advisories from the US cybersecurity agency CISA (ICS-CERT). We filter to vendors relevant to DACH industry and refresh daily, as CISA publishes new advisories.
Not necessarily. An advisory describes a reported flaw in a product. Whether your specific plant is affected depends on version, configuration and patch level – the original vendor/CISA advisory clarifies that.
Large vendors with very broad, globally deployed portfolios (like Siemens) publish correspondingly more advisories. The absolute number is not a measure of “insecurity”.
Whether AI in production or connected OT: we bring new technology into operation securely.
These tools cover related ground.